🇺🇦 Hacken was born in Ukraine, and we stand with all Ukrainians in our fight for freedom!

🇺🇦 Hacken stands with Ukraine!

Learn more

Cyber Security Score Review

Cyber Security Score Review

Published: 9 Aug 2018 Updated: 22 Sep 2022

Kraken exchange has the highest Cyber Security Score (9.23 points) because it has perfect SSL/TLS connection, domain security, and good application security (10, 10, and 7.92 points respectively). Cex.io is just 0.05 points behind the leader and lags slightly when it comes to domain security (9.82 vs 10.00). Binance has perfect application security as well as SSL/TLS connection, but it falls behind when it comes to domain security with just 6.70 points. Therefore, it moved to the 3rd position on the CSS rank with 9.01 points. It is worth noting that Kucoin is the only exchange covered by CER that has a very low estimated SSL/TLS connection. Also, we should consider that 15 out of 18 crypto exchanges have similar Domain Security subtotals, and only Kucoin, which is far behind all other exchanges, has a remarkably low rank.

Components of Cyber Security Score to count on

Here’s a detailed description of the components of each subtotal. APP LVL Security (Application level security) includes:

  • Server security (SS) – the protection of information assets that can be accessed from a Web server.
  • Captcha (C) â€“ website and user protection from automatic actions (brute force, spam etc.).
  • Multi-factor authentication (MFA) â€“ an additional level of security that protects the accounts of users.

SSL/TLS connection has the following structural units:

  • Compliance with requirements (CR) â€“ checks for outdated SSL / TLS algorithms in server settings. Outdated algorithms allow hackers to decrypt user traffic and gain access to logins/passwords
  • Most recent SSL/TLS vulnerabilities and weaknesses (VW) â€“ checks for the known SSL / TLS vulnerabilities. These vulnerabilities allow hackers to decrypt the traffic and gain access to logins/passwords, the server, private keys, etc.
  • Presence of third-party content (TPC) â€“ if a website contains third-party content and uses HTTP transmission, an attacker can replace the transmission with another one and steal the accounts of users.

Domain security, in turn, has the following components:

  • SPF domain records (SPF) â€“ verify the letter sender and protects from forgery (email spoofing).
  • DNSSEC records (DNSSEC) â€“ protects users from a substitution of IP-address (example: original – binance.com:192.168.2.20, fake – binance.com:133.10.10.1).
  • Web application firewall (WAF) â€“ protects exchanges from various attacks; sqli, rce etc.

How to compare exchanges by CSS

Table 2 shows the Top-3 crypto exchanges with the highest CSS ranks

Even though Kraken has a low Captcha component compared to that of Cex.io and Binance, and, therefore, only has an  APP LVL Security subtotal of 7.92 (10.00 for Binance), this exchange still holds the 1st position due to the perfect SPF domain records component, and, as a result, has a Domain Security subtotal of 10.00. This allows Kraken to overperform Binance by CSS. Binance, as described above, has perfect APP LVL Security and SSL TLS connection subtotals, but the absence of DNSSEC records and, as a result, the DNSSEC component score of 0 lowered the Domain Security subtotal to 6.70 (from Table 1, we can see that this score is average). For this reason, Binance finished 3rd.

Table 3 shows the Bottom-3 crypto exchanges, which have the worst CSS scores.

Kucoin occupies the last position of our CSS rating. It is the only exchange that has no web application firewall. Therefore, despite scores similar to those of the other  Bottom-3 exchanges in SPF and DSSSEC, Kucoin`s Domain Security score is 2.85 (for Gemini and Exmo it is 6.70). Further, Kucoin is the only exchange that has a very low estimated SSL/TLS connection due to a messy system structure. The total SSL/TLS connection for this crypto exchange is only 2.00 (against 10.00 points for all other exchanges covered by CER). It is worth noting that Kucoin scored relatively higher on application security (5.83 vs 4.10 and 3.82 for Gemini and Exmo respectively).

Conclusion

Cybersecurity in the modern world is crucial. Computer networks have been susceptible to attacks since they were created, and it seems that the threat of cyber-attacks will grow along the networks. Fortunately, proper equipment and specialists make it much easier to detect potential attacks and restore losses from cyber attacks. Cyber Security Score by CER gives you an idea of the possible risks associated with trading on certain crypto exchanges.
Therefore, if you learn how to utilize the CER Cyber Security Scoring to the full extent, you’ll simply determine which exchange isn’t secure for holding your funds.   

Make the right decisions, choose riskless exchanges while CER is free!

Share your experience of using CER in …
Telegram
Reddit
To stay updated on the latest CER news follow us on
Twitter
Telegram Channel

share via social

Subscribe to our research

Enter your email address to subscribe to Hacken Research and receive notifications of new posts by email

Interested in getting to know whether your systems are vulnerable to cyberattacks?

Tell us about your project

  • This field is required
  • This field is required
    • telegram icon Telegram
    • whatsapp icon WhatsApp
    • wechat icon WeChat
    • signal icon Signal
  • This field is required
  • This field is required
  • This field is required
  • This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Apply for partnership

  • This field is required
  • This field is required
  • This field is required
  • This field is required
    • Foundation
    • VC
    • Angel investments
    • IDO or IEO platform
    • Protocol
    • Blockchain
    • Legal
    • Insurance
    • Development
    • Marketing
    • Influencer
    • Other
This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Get in touch

  • This field is required
  • This field is required
  • This field is required
  • This field is required
This field is required
By submitting this form you agree to the Privacy Policy and information beeing used to contact you
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo